Use the Enricher Module to gain additional context about alerts in your environment. The Enricher adds Trellix intelligence to the existing information about a file, event, or alert displayed in the Endpoint Security Web UI.
This additional intelligence helps to determine when a file is malicious and assists in the incident response investigations. Enrichment provides an automated workflow that collects and analyzes artifacts, which reduces the time it takes to prioritize malicious activity in your enterprise.
The Enricher Module is a server-only feature and does not require any agent functionality to be installed. Unlike some modules, the Enricher Module does not have a host set policy component. When you enable the Enricher Module, it is enabled for all hosts.